The SaaS publisher Board of Cyber has released a panorama assessing the external attack surface of 21,700 French entities subject to the NIS 2 directive.
Expected to be on the agenda of the July extraordinary parliamentary session, the bill concerning “the resilience of critical infrastructures and the strengthening of cybersecurity,” which implements NIS 2 into French law, was not included.
This ongoing postponement pushes the discussion to September, although no date has been set yet.
This legislative gridlock did not deter Board of Cyber, which drew on ANSSI’s Cyber France Reference Framework (ReCyF) to analyze 2.8 million assets.
The overall average score stands at 690 out of 1000, placing the national ecosystem at an intermediate maturity level.
A collective standstill at the intermediate maturity level
The analysis highlights a massive concentration of organizations in the middle of the maturity scale. 59.4% of entities fall into the intermediate category, while 32.7% reach the advanced category and 7.9% remain at the basic level.
Nearly one in five entities (18.1%), all within the intermediate category, sits within less than 50 points of the advanced threshold. A milestone the study calls difficult to cross, noting that 50 points are not earned in a single move.
The landscape is also characterized by deep sectoral disparities.
The banking sector stands out with 60.2% of its entities in the advanced category.
In contrast, the digital sector (which constitutes the common backbone of the 18 sectors covered by the directive) proves the least mature, with only 28.1% of entities in the advanced category.
Worse still, it concentrates 81% of basic-level structures and is the only sector to receive a Grade C in messaging. As a result, it alone accounts for 64.8% of the critical vulnerabilities observed on the market.
The concentrated threat of the supply chain
Under Article 21.2.d of the directive, the regulatory challenge goes far beyond protecting a company’s internal perimeter.
It requires identifying critical third parties, assessing the risks they introduce, and monitoring their security levels over time. Yet panorama data reveal a worrying asymmetry: if two-thirds of potential suppliers do not reach the advanced level, the real threat rests on a minority of players.
Indeed, 10% of entities concentrate 93.1% of critical vulnerabilities while being integrated into the supply chain of the entire market.
Even more striking, 13.6% of companies classified in the advanced category also harbor at least one critical flaw that could be exploited to cascade to their partners.
Add to that an external attack surface that remains poorly controlled for nearly a third of organizations (34.8% rated D or E in this domain, which covers open ports and Internet-facing administration interfaces).
“These indicators sketch a two-speed landscape where risk is heavily concentrated. If the majority of companies stay at the intermediate level, the real threat rests on a minority that bears most of the critical vulnerabilities while being present in the supply chains across the market,” notes Sylvain Lefeuvre, Deputy CEO of Board of Cyber.
The study thus calls for a paradigm shift in operation, structured around three axes: raising the common level across the chain, pooling assessments among contracting authorities to avoid time-consuming and costly individual audits, and sustaining remediation efforts over the long term.
A governance imperative as the regulatory deadline approaches.